20,000 Searches Per Ticket Sold. Five Years of Litigation Proved $2,457.72 of Harm.
Fare scraping is an infrastructure and margin problem, not a legal one, and the automation hitting your search endpoints now includes your customers' shopping agents. Here is what to measure, what to verify, and what to charge for.
Your search platform will answer somewhere between ten and twenty thousand queries today for every ticket it sells. Just under half the traffic doing the asking will never fly anywhere.
Here is what a single one of those queries costs. A customer pulling up a month of fares can fan out to roughly 450 AirShopping requests against your passenger service system. The scraper triggering the same request pays about a sixth of a cent.
That asymmetry is the whole business problem, and the obvious answer is to make it stop. There are two ways to try: sue the scrapers, or block them. Ryanair did both, with more money and more appetite than anyone else in the industry.
Take the lawsuit first. Five years against Booking.com under the Computer Fraud and Abuse Act, a four-day jury trial, and a verdict the airline announced as a win.
Total harm it could actually prove: $2,457.72. The statute demands $5,000 before liability attaches at all, so the judge threw the verdict out and Ryanair walked away with nothing.
Blocking went no better. Its program of screening and blocking intermediary bookings is now being contested in front of Italy’s competition authority with a 255.8 million euro number attached.
So both instincts have been stress-tested at scale by the carrier most willing to fund them. This piece prices the problem in figures you can check yourself, shows exactly where each exit closes, and lays out the third path: charging for expensive traffic instead of arguing with it.
The short version: travel sites run 49% bad bot traffic against 45% human, per the 2026 Thales Bad Bot Report. Look-to-book has drifted to 10,000 to 20,000 searches per ticket sold. An unblocked page fetch and a solved CAPTCHA each cost an attacker around a sixth of a cent, while the query behind them can trigger 450 AirShopping requests on your side. Litigation has produced almost nothing, aggressive blocking has its own price, and a growing slice of the automation is somebody’s shopping agent that behavioral detection can no longer separate from a scraper. What works is a sequence, not a product: discover the full API surface, verify identity with cryptography instead of user-agent strings, then charge for access in cost-weighted quotas.
The arithmetic that never makes it into a board deck
In October 2025 IATA published a white paper on look-to-book drawn from a workshop with 14 airlines and more than 20 interviews with IT providers and sellers. It is the most candid document the industry has produced on this, mostly because it is not selling anything.
- Leading airline IT providers field 3 to 13 billion shopping requests a day. Large metasearch engines generate up to 100 billion.
- One customer asking for a month of fares can become roughly 450 AirShopping requests.
- Stakeholders told IATA they believe more than 80% of the offers an airline builds are never shown to a customer. IATA calls this an often overlooked measure, which is a polite way of saying nobody tracks it.
- Because most carriers still run NDC and EDIFACT side by side, sellers query both, which in IATA’s words effectively doubles the looks with no increase in bookings.
OAG’s July 2026 analysis puts today’s reality at ten to twenty thousand searches per ticket sold. You will see 200,000 quoted alongside it; that traces to one PhocusWire opinion column, so treat it as an informed projection rather than a measurement.
Here is the honest gap: nobody publishes a credible per-search cost. The vendor figures that circulate are unsourced, and we are not going to launder them.
What you can price is the ticket side, and it makes the strategic point better anyway. Lufthansa Group’s distribution cost charge guideline, effective May 5, 2026, charges 19.00 euros per ticket through Amadeus, 22.50 through Sabre, 23.00 through Travelport. Its own channels and NDC bilateral model carry no DCC at all.
Read that gap twice. The channel a booking arrives through sets its margin. The channel a search arrives through sets its cost. And if a large share of your search volume is automated polling, your demand curve is describing scrapers rather than shoppers, so revenue management is pricing against noise.
Just under half your traffic, and it will never book
The 2026 Thales Bad Bot Report, published April 29 on full-year 2025 data, is the cleanest public read available. Web-wide, automated traffic reached 53% of requests, bad bots 40%, humans down to 47%.
Travel specifically: 49% bad bot, 6% good bot, 45% human.
One correction worth making internally. Travel was the most attacked industry in the 2025 edition of that report. In the 2026 edition financial services takes the top spot at 24% of all bot attacks, and travel sits fourth by share of bad bot traffic. If your deck still leads with travel at number one, it is a year stale.
The category that matters here is business logic abuse, where travel ranks second at 17% behind retail at 24%. These are the attacks that break nothing and trip no signature, because every request is valid. The report’s travel section describes it precisely:
“[…] Analysts observed high-frequency queries to fare, seat, and route APIs, often far exceeding normal customer behavior. Fetch-style automation continuously polled systems during peak periods, masquerading as legitimate agents to inflate look-to-book ratios and distort demand signals used for pricing and capacity planning. Seat spinning and denial-of-inventory attacks created artificial scarcity, reducing availability for legitimate customers and impacting both revenue and customer experience.”
Akamai’s commerce research from July 15, 2026 adds scale. Across more than 17 trillion bot requests against commerce platforms in 2025, travel took 34% of the activity, second only to retail. In North America, 41% of commerce bot activity targeted travel, which Akamai attributes largely to an attempted browser-impersonation campaign intended to steal customer credentials across a wide partner ecosystem. Between January 2024 and December 2025, 49% of commerce web attacks hit API endpoints.
Your search, availability and pricing endpoints are the product. They are also the part of your estate that answers to anyone who asks politely.
Read the attacker’s price list. It is published.
None of it is secret, which is why it tends to change the temperature of a meeting. We checked the vendors this week.
Bright Data lists residential proxy bandwidth from $8 per GB down to $5 at volume and prices its unlocking API at $1.50 per 1,000 requests. Oxylabs starts residential at $6 per GB, falling to $2.50 on terabyte-scale commitments, with its scraper API from $0.50 per 1,000 results. 2Captcha prices Cloudflare Turnstile solves at $1.45 per thousand.
Round it off:
- One unblocked page fetch: about $0.0015
- One solved Turnstile: about $0.00145
- One calendar query on your side: 450 AirShopping requests
The asymmetry is not in the price per unit. It is in what a unit means on each side of the exchange. The attacker pays list price and still wins.
The tooling has kept pace. Thales categorizes what its analysts saw in 2025 and it reads like a maturity curve: residential and mobile proxy networks that make IP reputation close to useless, headless frameworks like Puppeteer and Playwright now driven by AI-generated scripts, CAPTCHA solving that blends automated solvers with paid human farms, and bots-as-a-service platforms that delete the skill requirement entirely. Fifty-eight percent of attacks were rated advanced or moderate, and analysts watched bots adapt within hours of a mitigation going live.
If you are hoping fingerprinting holds the line, Akamai settled that in May 2019. Attackers began randomizing TLS cipher suites, and distinct fingerprints observed globally went from 18,652 in August 2018 to billions inside six months. The named targets were airlines, banks and dating sites. Fingerprints are a signal. They were never a wall.
Exit one: sue them. Five years proved $2,457.72 of harm.
The anatomy of that number is worth walking through, because it shows precisely which door closed.
A jury found in July 2024 that Booking.com violated the CFAA by encouraging a third party to log into the myRyanair section of Ryanair’s site. Damages: $5,000, precisely the statutory minimum the CFAA requires before civil liability attaches.
Then Judge William Bryson, a Federal Circuit judge sitting by designation in Delaware, worked through Ryanair’s roughly $177,000 of claimed loss line by line. Verification costs had been passed on to customers, so they were not Ryanair’s losses. Customer service salaries were never apportioned to the conduct. Navitaire fees were an ordinary cost of doing business. What survived was part of the anti-bot hosting bill, at most $2,457.72. Below the threshold. Judgment as a matter of law for Booking.com, January 22, 2025. Ryanair appealed, withdrew on August 26, 2025, and announced a commercial partnership with Booking Holdings the same day. No appellate ruling exists, and the judgment left standing says Booking.com never violated the Computer Fraud and Abuse Act at all.
The part nobody quotes is the earlier summary judgment order. Bryson held that any user can reach any page on Ryanair’s site without prior authorization, with one exception: the final payment page inside myRyanair. Scraping public fare displays was not unauthorized access.
The wider record is no kinder:
- hiQ Labs v. LinkedIn is the leading appellate decision and much narrower than its reputation. The Ninth Circuit affirmed a preliminary injunction in 2022 on the basis that hiQ had raised serious questions, expressly excepted password-protected areas, and hiQ lost on breach of LinkedIn’s user agreement anyway.
- Ziff Davis v. OpenAI (S.D.N.Y., December 2025): robots.txt is not a technological protection measure under the DMCA. Such files “do not ’effectively control’ access to that content any more than a sign requesting that visitors ‘keep off the grass’ effectively controls access to a lawn.”
- Google v. SerpApi (N.D. Cal., July 2026): DMCA claims over bypassing an anti-bot challenge, dismissed.
- RFC 9309 says it about itself. Its rules “are not a form of access authorization,” and the protocol is “not a substitute for valid content security measures.”
Europe is less friendly than the standard citation suggests. The CJEU’s 2015 Ryanair v PR Aviation left enforceability of terms to national law, and on remand the Hague Court of Appeal applied Irish law, found Ryanair’s browse-wrap formed no contract, and awarded costs against the airline. Germany’s Federal Court of Justice held in 2014 that a terms-acceptance checkbox is not a technical protective measure.
One case is still live. In Amazon v. Perplexity, Amazon won a preliminary injunction in March 2026 over the Comet browser logging into customer accounts, arguing access can be authorized by the user and unauthorized by the site. The Ninth Circuit stayed it, heard argument on June 11, and has not ruled. Whether a customer can lend credentials to an agent decides a great deal for travel.
Exit two: block them. Ryanair is contesting 255.8 million euros.
On December 19, 2025, Italy’s competition authority fined Ryanair 255,761,692 euros for abuse of a dominant position. The conduct at issue was the anti-intermediary program itself. Ryanair verified the identity of passengers who had booked through agencies and not those who booked direct, blocked agency bookings and payment methods, deleted accounts linked to OTA bookings en masse, and branded non-signatory agencies as pirates. Ryanair has provisioned 85 million euros and is appealing.
Be precise about what that case is. It is a commercial-blocking dispute, not a bot-management one, and deploying a scraper defense does not create antitrust exposure in Italy.
Then notice the pairing anyway. The carrier that pushed hardest on both exits proved $2,457.72 of harm in Delaware and recovered none of it, and is contesting a nine-figure fine in Rome. Akamai’s own researchers put the underlying point more briefly in their scraping research: scraping public content is not inherently illegal.
You do not need a stronger deterrent. You need to tell the automation you want from the automation you do not, precisely enough that you never block a paying customer or a partner you are contractually obligated to serve.
Which brings us to the reason that just got harder.
The complication nobody planned for: some of the bots are buying
HUMAN Security publishes a monthly read on agentic traffic. Its June 2026 figures put travel at 13.5% of all agentic traffic, up 14% month over month, with Perplexity’s Comet accounting for 47.6% of agent activity.
Now the split that reframes everything: 79% of agent requests hit product and search paths. Only 2.34% reached checkout.
Agentic traffic today is search traffic. DataDome counted 17.7 billion AI agent requests in the second quarter, up 45% quarter over quarter, and found Meta’s two agents alone made up more than half of all AI traffic while returning almost no referral value.
Writing as a guest contributor in Akamai’s commerce report, Pam Lindemoen of the Retail and Hospitality ISAC names the detection consequence: autonomous shopping agents create a signal masking problem by mimicking human microbehaviors closely enough that the behavioral signals you rely on stop separating populations.
Sit with that. Mouse movement, dwell time, interaction cadence. None of it was ever proof of humanity. All of it was a proxy, and the proxies have been solved.
The plumbing is real, meanwhile. Mindtrip launched flight booking in May 2026 on Sabre’s agent-ready air APIs with PayPal handling payment, and Travelport launched TripServices in June on the premise that agents need deterministic, normalized APIs.
Consumers, though, have not shown up. Skift Research measured in 2025 that only 2% of US consumers would let AI book for them, and Expedia’s April 2026 research across US and UK travelers found just 8% use AI platforms when planning a trip. But Expedia found the number that actually matters for your planning: 42% said they would use AI to monitor prices and time their booking.
That is the near-term shape of agentic travel, and it is not a booking channel. It is a population of agents that search constantly and buy rarely, acting for customers who fully intend to buy eventually. The first wave arrives as a look-to-book problem wearing a customer’s face.
Two notes before the fix. Do not write product names into policy: OpenAI’s Atlas browser launched in October 2025 and stops working on August 9, 2026, so any allow-list built on this year’s brands needs rewriting next year. And there is an opening sitting wide open. As far as we can establish, no individual airline has published an agent-facing API or a public policy on AI agent access. IATA’s white paper asks sellers to declare their “AI agentic policy,” so the paperwork exists. The policies do not.

Exit three: stop asking permission and start charging rent
Three steps, and each is worthless without the one before it. You cannot verify a caller on an endpoint you never inventoried, and you cannot price a request whose cost you have not measured.
Discover, because you cannot meter what you have not found
Akamai’s commerce research found that only 22% of organizations know which of their APIs expose sensitive data. On travel platforms the picture is usually worse, for structural reasons rather than sloppy ones. Mobile apps have their own endpoints. Partners were integrated years ago by people who have since left. NDC and EDIFACT paths coexist. Loyalty sits on a separate stack, and loyalty balances have become a currency criminal syndicates target directly. And somebody has almost certainly stood up an MCP server for an AI pilot without telling security.
API discovery that finds shadow and zombie endpoints and flags which ones touch personal data is the unglamorous step that makes the rest possible.
Verify, and prefer proof to reputation
DataDome publishes a signal strength table in its documentation that is the most useful engineering statement on this we have seen this year:
- High confidence: Web Bot Auth signatures, cryptographic token verification, trusted IP source lists, reverse DNS
- Medium: network attribution, client-side fingerprinting
- Low: server-side fingerprinting
Simple enough for a whiteboard. Anything the client asserts about itself is weak. Anything the client cannot forge is strong.
The mechanics are the ones we walked through in our piece on telling real agents from impostors: an Ed25519 key pair, a public key at a well-known path, request signatures under RFC 9421, verified at the edge in milliseconds. What travel adds is placement. An AirShopping request that fans out across 450 upstream calls needs its identity established before the fan-out.
Be honest about the standards status, because vendors sometimes are not. The core document is still an individual Internet-Draft, revised on June 26, 2026, and its datatracker page says plainly that it has no formal standing in the IETF standards process, even with a working group now chartered around it. It is in production regardless: Cloudflare validates these signatures at its edge, AWS added support to WAF Bot Control on July 14, and Akamai described its own edge validation in November 2025 as moving bot management from heuristic detection toward verifiable identity. Deployable now, standardized later.
Price it, rather than denying it
Here is where travel diverges from retail, and where most of the deployments we inherit went wrong.
Count cost, not requests. A calendar query that fans out to hundreds of upstream calls is not one unit of work, and a quota that treats it as one lets a single client that looks well behaved eat the platform. Weight quotas by the origin work a route triggers, and apply them per token and per session, since residential proxy pools make IP-based counting close to meaningless.
Segment sellers deliberately. IATA is refreshingly direct that the crude version is a mistake: throttling on look-to-book ratio alone is not an optimal approach, because the ratio never tells you whether a seller is inefficient, experimental or abusive. Their preferred direction pairs seller segmentation with a search-origin identifier on every request, so the caller declares who it is and what the search is for. That beats the spreadsheet of IP ranges most platforms run today.
Use the whole ladder: monitor, meter, tarpit, challenge, deny. Akamai’s scraper-specific tooling exposes graduated responses including tarpits for this reason, and its own commerce report states that blanket blocking is not viable, with more than 90% of AI bot activity sitting in monitor rather than deny. Slow usually beats blocked. A tarpitted scraper burns its own proxy budget, while a blocked one is back in ten minutes with a fresh fingerprint.
One limit to state plainly: verification proves identity and says nothing about intent. A validly signed agent running 400 searches a minute is still a look-to-book problem, so the cost gate applies to verified callers too.
Where this gets uncomfortable
Mobile is the blind spot. Browser-based detection relies on executing JavaScript, and a native app has no browser. Scrapers moved accordingly, reverse engineering app APIs and driving traffic through emulators, which is why Akamai shipped a native app SDK for scraper protection in March 2026. Endpoints your web defenses never see are the cheapest surface an attacker has.
Commercial obligations constrain the technical answer. Price parity expectations, full content agreements and metasearch relationships all oblige you to serve queries that look, at the packet level, exactly like abuse. Any policy that cannot express “this partner gets 40 million searches a month and this one does not” will end up either blocking revenue or permitting everything.
Challenges are not free. We ran the arithmetic on what challenge-based defenses cost at real volume, and per-request pricing under automated traffic gets expensive fast.
The agent layer is its own attack surface. On July 17, 2026, Akamai published a walkthrough of a prompt-injection chain against a fictional travel AI agent that ends in a booked flight nobody paid for. If you expose an agent, its back-end APIs have to validate state independently rather than trusting what the agent layer asserts.
And on vendors, a data point rather than a recommendation. Forrester renamed this category in late 2025, from bot management to bot and agent trust management, then ran its first Wave under the new name in June 2026, naming DataDome, HUMAN Security and Kasada as Leaders. We deploy and operate Akamai, and think its scraper-specific detection and API discovery are strong for travel workloads. Both can be true. If a vendor tells you the category has not changed, they have not read the market.
Five numbers, reviewed monthly
- Look-to-book by seller segment, never in aggregate. The aggregate hides everything. Broken out by declared caller, it usually names your most expensive sellers inside a week.
- Offer-to-Order and CPU-to-Order. IATA’s proposed metrics beat look-to-book because they account for the compute a search consumes rather than just counting it.
- Proof coverage, split by channel. What share of automated traffic can cryptographically prove who it is, broken out by NDC versus EDIFACT. Almost nobody has that second breakdown before they go looking.
- False positives, counted separately for verified agents and for human sessions on mobile networks. Both are revenue leaks that report as successes on a security dashboard.
- Cost per booking, split into origin, cloud and distribution. The only number that gets a finance director’s attention, and the one that funds the next phase.
Four weeks, mostly in observe mode
Which is why this does not put bookings at risk.
Week 1: count. Discover the full API surface including mobile and partner paths, then measure look-to-book by claimed caller identity. Act on nothing. This week usually produces the number that reorders the roadmap.
Week 2: verify. Turn on signature validation and forward-confirmed reverse DNS at the edge. Tag every automated request with the strength of proof it offered, and separately tag the channel it arrived on. Still observing, so this week’s arguments cost nothing.
Week 3: weight. Build cost-weighted quotas for search, calendar and availability routes, per token and per session. Write the seller segments down explicitly, including partners with contractual entitlements. Publish an agent access policy, even a short one, because you want a public position before the first agent operator asks for an exception.
Week 4: enforce. Graduated responses, money endpoints first. Stand up the five numbers and put the review on someone’s calendar. After that it becomes tuning, which is the only mode bot management has ever really worked in.
The industry spent fifteen years asking whether it was allowed to stop the scrapers. Courts in Delaware, New York, Karlsruhe and The Hague mostly answered no, or not on these facts, or not without a better theory. Rome answered that trying too hard has a price of its own.
What changed this year is not the law. Proof got cheap. An agent can now demonstrate cryptographically who operates it, your edge can verify that in the time it takes to route a packet, and a request’s cost can be measured in the origin work it triggers instead of guessed from its IP address. That buys you what the blocking era never offered: the ability to say yes to expensive traffic on terms you set, and no to everything else without going to court over it.
Ryanair’s five years produced $2,457.72 of provable harm, no recovery, and an antitrust file. A weighted quota and a signature check cost four weeks. No airline has published an agent access policy yet, so whoever moves first writes the terms the rest inherit, and everyone else will still be blocking by user-agent string while a competitor takes the booking.